Huawei Update
3687Warning Date
Severity Level
Warning Number
Target Sector
9 September, 2019
● Critical
2019-413
All
Description:
Huawei has released security Update to address vulnerabilities in the following products:
- P30 Smartphone Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1)
- P30 Pro Smartphone Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1).
- Mate 20 Smartphone Versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1).
- HiSuite Software Versions earlier than HiSuite 9.1.0.305.
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.
Best practice and Recommendations:
The CERT team encourages users to review Huawei security advisory and apply the necessary Updates:
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190904-01-smartphone-en
- The product that supports automatic update will receive a system update prompt. You can install the update to fix the vulnerability.